Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers.…
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers.…
Incident Overview and Compromised Data On July 13, 2026, security teams verified that unauthorized actors had compromised Chick-fil-A One profiles using an automated credential stuffing…
Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across…
A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of…
Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems Pierluigi Paganini July 25, 2026 US agencies warn Iran-linked actors are targeting internet-exposed water…
Over the last few decades, several mysterious hackers have captured the public’s imagination, but none quite like Phineas Fisher. A decade after their most famous…
As cloud adoption accelerates, Security Operations and incident responders are facing a defining moment. Traditional detection and response tooling built for endpoint and on-prem infrastructure…
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin. The…
A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve…
According to Mandiant’s M-Trends 2025 report, when organizations discover a ransomware intrusion on their own (without being tipped off by law enforcement or, ironically, by the…
A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and…
Ransomware activity followed a recognizable pattern during the previous four years. Each year was defined by a dominant actor, its collapse, or a major supply…